package cn.rengy.web.framework.sql;


import org.springframework.jdbc.core.namedparam.SqlParameterSource;

import cn.rengy.tool.core.TokenHandler;

public class SqlVariablesHandler  implements TokenHandler{
	private  SqlParameterSource sqlParameterSource;
	
	public SqlVariablesHandler(SqlParameterSource sqlParameterSource) {
		this.sqlParameterSource=sqlParameterSource;
	}
	@Override
	public String handleToken(String content) {
		Object variableValue=sqlParameterSource.getValue(content);
		//校验sql注入delete union update 
		if(variableValue==null) {
			return "";
		}
		return variableValue.toString();
	}

}
